One of the tools that allow detecting alterations in the Linux file system is Tripwire. It is an Open Source data integrity and security software that monitors and alerts any changes that are registered in the system files.
The operation is based on the collation of the digital signature of the files and directories with a previous database of them. The database is generated by taking a snapshot at the time of installing or creating a file, and can only be accessed through an encrypted password. To guarantee its effectiveness, it must be installed and configured before connecting the device to the Internet for the first time.
Other similar tools are AIDE and Samhain, which offer features and functionalities that are very similar to Tripwire.
Source: Opensource.com
0 Comments